Redefining Technology

Construction & InfrastructureRegulations, Compliance & Governance

GDPR and data governance for AI on construction and infrastructure projects

Project data governance under GDPR is the discipline of knowing which personal data a construction or infrastructure site creates — camera footage, biometric templates, access logs, drone imagery — deciding which company in the chain is the controller for each of them, and settling what happens to all of it when the project reaches handover.

Site team in PPE reviewing a data-governance overlay on a live construction project, with plant and part-built frame behind them
Construction & Infrastructure · Regulations, Compliance & Governance

Key takeaways

  1. A construction site is the hardest personal-data environment in industry because it is a temporary workplace staffed by other companies' people: one camera network watches employees of the main contractor, six subcontractors, two labour agencies and the client's own inspectors, and none of them share an HR system.
  2. Site CCTV with computer vision — PPE detection, exclusion-zone alerts, plant-proximity warnings — is systematic monitoring of workers, so a DPIA is required before the system is energised, not after the first incident it detects.
  3. Biometric turnstiles process special category data under Article 9, and the necessity test is unforgiving: the ICO ordered Serco Leisure and associated trusts to stop processing the biometric data of more than 2,000 employees for attendance checking and to destroy it, because cards and fobs were a less intrusive option.
  4. In a joint venture the joint-controller question under Article 26 is answered whether or not anyone writes it down — and if nobody does, every JV member carries the full controller obligation for everything the shared site systems did.
  5. The retention question nobody plans for is handover: at practical completion the project stops existing, and four years of footage, access logs and biometric templates need an owner, a deletion date or a documented transfer — decided at contract award, not on the last day.

Abbreviations used on this page

GDPR
General Data Protection Regulation (EU) 2016/679, and UK GDPR in Great Britain
DPIA
Data protection impact assessment (GDPR Article 35)
LIA
Legitimate interests assessment — the three-part test behind Article 6(1)(f)
RoPA
Records of processing activities (GDPR Article 30)
DPO
Data protection officer
CDE
Common data environment — the project's shared information store under ISO 19650
CDM 2015
Construction (Design and Management) Regulations 2015
JV
Joint venture — two or more contractors delivering one project as a single entity
PC
Practical completion — the point at which the works are handed to the client
CV
Computer vision — image models such as PPE detection or exclusion-zone alerting
ANPR
Automatic number-plate recognition, typically on the site gate
EDPB
European Data Protection Board

Free · 8 questions · ~3 minutes

Score your project on the governance ladder

Eight questions, one at a time, about three minutes. Answer them and we build your personalised project report — your stage on the ladder, your score on each of the four dimensions, and the specific gap a client's auditor, a union representative or a regulator would find first — and send it to your inbox. Your result doubles as the scoping input for a site data register and DPIA programme.

0 of 8 answered

Question 1 of 8Personal-data inventory

If your client's DPO asked today, could you list every system on your largest live site that captures personal data?

The register is the foundation every other obligation stands on. A project that cannot list its cameras, readers and tags cannot defend any of them.

How the score maps to a stage
  • 05 — Stage 1, Unmapped. The site creates personal data continuously and nobody can name the systems, the purposes or the companies that hold it.
  • 611 — Stage 2, Inventoried. A register exists and the paperwork looks finished, but it describes the company rather than the project — and nothing on site enforces what it claims.
  • 1216 — Stage 3, Controlled. Controls are enforced in the site systems themselves: assessments precede energisation, models run on the narrowest useful data, and retention is set where the footage lives.
  • 1721 — Stage 4, Evidenced. The project can prove it: a live register, assessments tied to site changes, a written joint-controller arrangement, consultation records and an agreed handover data schedule.
  • 2224 — Stage 5, Trusted. Governance travels with the work: it is asked for at prequalification, flowed down in subcontracts, and closed out at handover as a priced, certified deliverable.

What GDPR data governance means on a construction project

Why a temporary site staffed by other companies' people is the hardest personal-data environment in industry — and the path that data actually takes, from the turnstile to the client's asset record.

GDPR data governance on a construction or infrastructure project is the discipline of knowing which personal data the site creates, deciding which company in the chain is the controller for each of those flows, and settling what happens to all of it at handover. The site systems that matter are the ones bought as operational kit rather than as data systems: cameras running computer vision for PPE and exclusion-zone alerting, biometric or card turnstiles, wearables and proximity tags, drone and 360 capture, plant telematics that identifies its operator. Every one of them processes information about identifiable people, so the General Data Protection Regulation (opens in a new tab) applies in full — and on a project it applies to several companies at once.

What makes a site different from a factory or an office is that the workplace is temporary and the workforce belongs to somebody else. A large project gate admits employees of the principal contractor, of six or more subcontractors, of two labour agencies, of the client's own inspection team, plus delivery drivers, statutory undertakers and visitors — populations that share no HR system, no induction database and no employment relationship. The camera that watches the deck watches all of them. The turnstile that records their arrival records them for a supplier's platform. Nobody in that picture has the single, tidy employer–employee relationship that most workplace monitoring guidance assumes, which is why the questions of lawful basis, transparency and controllership are harder here than anywhere else in industry.

The regulation does not prohibit any of this. It asks for an evidence discipline: a lawful basis for each purpose (Article 6 (opens in a new tab)), collection limited to what the purpose needs (Article 5 (opens in a new tab)), a stricter gate where biometric data is used to identify someone (Article 9 (opens in a new tab)), an impact assessment before high-risk processing begins (Article 35 (opens in a new tab)), a written allocation where two or more organisations decide purposes together (Article 26 (opens in a new tab)), transparency to the people in the data, and retention that ends. UK projects carry the same duties under UK GDPR, with the ICO's guidance on monitoring workers (opens in a new tab) as the operative reference. None of these obligations is AI-specific. What AI changes is that a camera which used to record for a security guard now evaluates every person in frame, continuously, and produces a searchable record of what they were doing.

This page reads those obligations through a five-stage project governance ladder — Unmapped, Inventoried, Controlled, Evidenced, Trusted — because the contractors who get into trouble are rarely the ones running monitoring; they are the ones who cannot account for it. The ladder is ordered by dependency: you cannot assign a basis to a system you have not registered, you cannot minimise data whose purpose is unstated, you cannot allocate controllership you have not analysed, and you certainly cannot close out at handover an archive nobody knew existed. The diagram below is the flow the whole page is about.

How personal data moves through a project, from the gate to the asset record

The same estate every large site now runs, drawn with the three moments that decide whether it is lawful: the induction join that turns a face or a tag into a named person, the point where several companies share one system and somebody decides its purposes, and practical completion, when the project stops existing and its archives need an owner.

  • Human in the loop
  • Data & feeds
  • Where value leaks
  • AI / model
  • System-of-record action

The process, in words

  • On site, the data is created by everyone and about everyone: the workforce of several employers, plus visitors and neighbours who never agreed to anything. Capture devices — cameras with computer vision, turnstiles, wearables, drones, 360 walkers — are impersonal only until the induction record joins a card, a face or a tag to a named person and their employer. That join is what makes the whole estate downstream a personal-data processing operation.
  • In the project systems lane, footage, access logs and progress imagery land on a platform that several companies can see, models raise alerts on it, and supervisors act. The decisive question here is not technical: it is who decided that this processing should happen and for what purpose. On a joint venture or a deep subcontract chain that decision is often collective and unwritten, which is exactly the condition Article 26 describes — and the subcontractor's own drone or camera adds data the project never specified and cannot account for.
  • At handover, the project ends and its archives do not. Recorders, cloud buckets and the supplier's platform hold years of imagery and access records; the information model going to the client carries site photography with identifiable people in it. Every item needs one of three answers — deleted, anonymised or transferred with a stated basis — and the only cheap moment to decide is contract award, because on the last day of a project nobody has budget, time or the supplier's attention.
Step-by-step insights
The induction join — where site telemetry becomes personal data
Project teams often argue that the camera watches 'the works, not people', or that the turnstile counts 'passes, not persons'. The argument fails because identifiability includes reasonably available means, and on a site those means are sitting in the induction system: every operative is registered against a name, an employer, a competence card and usually a photograph before they are allowed through the gate. One lookup joins the tag to the person. The design leverage lives exactly here — hold the induction identity in a separate, access-logged store, resolve identity only on a logged request, and most of the estate can run on tokens that mean nothing on their own.
Computer vision changes the nature of a camera that was already there
The most common governance mistake on sites is treating an analytics upgrade as an IT change. A camera recording to a loop for security is one processing operation; the same camera running PPE detection and exclusion-zone alerting is a different one — it evaluates every person in frame, continuously, and produces structured records of individual behaviour that can be searched, counted and compared. The EDPB's video guidelines make clear that video processing engages the regulation directly, and the practical consequence is simple: an analytics module switched on by a firmware update is a new purpose, and it needs its own assessment before it is energised.
The subcontractor's kit — capture you did not specify and cannot account for
A survey subcontractor flies a drone every Friday. A fit-out subcontractor runs a 360 walk for its own progress claims. A plant supplier's telematics identifies the operator to enforce licences. None of this appears in the principal contractor's register, and all of it happens inside a site the principal contractor controls, on people it inducted. The fix is procurement, not policy: capture activity is registered before it starts, terms cover retention and reuse, and the subcontract says plainly whether imagery may leave the project or train a supplier's models.
One system, six companies — the joint-controller moment
The shared site platform is where the controllership question becomes concrete. If the JV board specified the exclusion-zone model, the partners decided the purpose together and Article 26 applies whether or not the deed mentions it. If the principal contractor decided alone and merely gives subcontractors a login, it is the controller and they are recipients. If a subcontractor pulls footage into its own safety programme, it has become a controller for that purpose. Writing the allocation down does not create the obligation — it is the only thing that makes it manageable, because it fixes who answers the worker, the client and the regulator.
Purpose creep travels along the alert log
The exclusion-zone alert exists for safety, and everyone agrees. Then the commercial team asks for footage to defend a delay claim, the quality team wants to check who poured the slab, and a supervisor uses last Tuesday's clip in a performance conversation. Each request is reasonable in isolation and each one processes the data for a purpose the assessment and the notice never described. Keep a request log with the reason, the requester and the approval; it is the cheapest control on this page, and it is also the record that tells you when the estate has quietly become something else.
Practical completion is a data event, not just a commercial one
On the day the works are handed over, the organisation that made every one of these decisions dissolves. The project team demobilises, the site systems come down, the supplier's platform reverts to its own retention defaults, and the client receives an information model whose contents nobody has examined for personal data. Statutory duties continue — the health and safety file, and for higher-risk buildings the golden thread, both of which the client must be given — but four years of camera footage belongs to none of them. Decide the destination of each class at contract award, price the close-out, and demand a deletion certificate for whatever does not travel.

The five stages of project data governance, in detail

For each stage: what it looks like on a live site, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps project teams there, and what leaving costs.

The five stages are Unmapped, Inventoried, Controlled, Evidenced and Trusted, and they measure how far a project has travelled from creating personal data to being able to account for it — from a site that cannot list its cameras to one that hands over a priced, certified data position at completion. Each stage below is written for a project team rather than a buyer. The hallmarks describe conditions observable on a live site, the diagnostic signals are checks a reviewer can run this week with a site plan and a login, and the anti-pattern is the specific mistake most often made trying to leave that stage. The ladder is ordered by dependency, not by virtue: register before basis, basis before minimisation, controls before allocation, allocation before handover.

Select a stage

Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.

Stage 1

Unmapped

27% of operators sit here

The site creates personal data continuously and nobody can name the systems, the purposes or the companies that hold it.

Unmapped is not carelessness. Most contractors at this stage have a privacy notice, a data protection lead at head office and a corporate register that covers HR, payroll and the CRM. What is missing is the project: the live site is a separate data-creating organisation with its own systems, its own suppliers and its own population of people, and nobody has walked it. The obligations exist; the map that would let anyone discharge them does not.

The tell is procurement. Site security cameras are bought against a security budget by a project team under programme pressure, often as part of a hoarding and fencing package. Biometric turnstiles arrive with the access-control contract. Wearables come as a bundle with the plant hire. A subcontractor turns up with a drone and a 360 camera because the survey scope asked for weekly progress capture. Every one of these is a processing decision made by someone with no data-protection remit, on terms nobody read, and the analytics features are increasingly enabled by default.

This stage is uncomfortable to leave because the first honest walk-round always finds something: a camera pointing over the hoarding into a neighbour's garden, a people-analytics feature switched on by a firmware update, three years of footage on an NVR in a cabin that was supposed to be a 30-day loop. Leaders sometimes prefer not to look. That instinct is backwards — regulators reserve their sharpest findings for the organisation that could not answer, and the first question is always the inventory.

In practice

The camera estate nobody could list

A client's data protection officer asks a principal contractor a simple question about a large city-centre project: how many cameras are on the site, what do they see, and how long is the footage kept? The answer takes three weeks to assemble and arrives as a spreadsheet with forty-one entries — including nine cameras the security subcontractor installed and invoiced separately, two with people-counting analytics enabled by the supplier as a product update, and one covering the smoking shelter, which nobody could justify when asked.

What it looks like

  • No single list exists of the cameras, readers, tags and drones operating on the project
  • The camera contract was signed on site as a security purchase, not as a processing decision
  • Subcontractors bring their own capture kit and nobody has seen the terms
  • A worker's access request would be answered by phoning round the supply chain

Diagnostic signals you can check this week

  • Ask the project team for the site's camera and sensor list; at stage 1 it is compiled on request, not maintained
  • Walk the hoarding line and check what each camera actually frames — footpath, neighbouring windows, the welfare unit
  • Ask which subcontractors are capturing imagery on site and under whose terms; if the answer is 'the survey team', you are here
  • Ask what a worker would receive if they made an access request for their own site data, and how long it would take

Anti-pattern · Asking the supplier whether it is GDPR compliant

The instinctive first move is to email the camera or turnstile vendor and ask for confirmation that the product is GDPR compliant. The answer always comes back yes, and it is close to meaningless: the supplier is describing its own processing, while the decisions the regulation actually tests — why this system, watching whom, at what resolution, kept how long, seen by which of the six companies on site — are yours. A compliant product deployed for an unassessed purpose is an unlawful processing operation with good paperwork attached.

What holds you here

Nobody can name the systems, purposes and companies that touch personal data on the project, so every obligation is unanswerable rather than unmet.

Highest-leverage next move

Walk one live site and build the register: every capture device, what it sees, who bought it, who can watch it, and how long the footage survives.

Cost of leaving

Effort
4–8 weeks
Team
Project data lead plus the site manager, with the privacy lead part-time
Risk
Low — the work is a walk-round and a register; nothing on site changes yet
To next stage
2–4 months

If this is you, the next step is

A 2–3 week exercise: every camera, reader, tag and capture device on one project, with purposes, holders and retention recorded.

Map one live site end to end

Stage 2

Inventoried

38% of operators sit here

A register exists and the paperwork looks finished, but it describes the company rather than the project — and nothing on site enforces what it claims.

Inventoried is the most common stage on projects and the most deceptive, because the artefacts exist. There is a register with a CCTV row, a DPIA template signed by someone senior, a privacy notice in the induction pack and a line in the subcontract about compliance with data protection law. What is missing is the connection to this project: a company-level entry cannot describe a system that was configured on this site, by this security supplier, watching this population, with an analytics module added in month eight.

The structural problem is that governance and delivery never meet on a project. The register was written at head office from interviews; the site was set up by a team whose success is measured in programme and cost, buying from a supply chain that configures the kit. So the register says thirty days while the recorder keeps everything, and it says 'security purposes' while a supervisor is using last Tuesday's footage in a performance conversation. Neither party is lying — there is simply no mechanism that makes the paper true on the ground.

Time at this stage accumulates risk in a way that is specific to projects: it compounds into handover. Every month of unassessed collection deepens an archive that nobody has agreed how to close, and each new subcontractor inherits an environment where capture is normal and terms are absent. Contractors usually leave stage 2 under external pressure — a union challenge, a client's data protection officer, a neighbour's complaint about a camera. Leaving it deliberately, on the first project rather than the fifth, is considerably cheaper.

In practice

The DPIA that described a different site

A national contractor's assessment for 'site CCTV' was written in 2019, approved once and attached to every project since. On a hospital extension, the same document is on file — but the site now runs computer-vision PPE detection and exclusion-zone alerting added by the supplier as a software update, a biometric turnstile the access-control package specified, and a weekly drone flight by a survey subcontractor. The DPIA describes none of them. It is not a bad document; it is a document about a different site, and the first person to notice is the client's auditor.

What it looks like

  • The corporate register mentions 'site CCTV' generically, with no entry for computer-vision analytics
  • One company-wide DPIA is reused for every project, including sites it never described
  • The privacy notice sits in the induction pack; workers learned about PPE detection from the toolbox talk
  • Retention is stated as 30 days while the recorder overwrites only when the disk fills

Diagnostic signals you can check this week

  • Ask for the DPIA covering the site you are standing on, then check whether it names the analytics features actually running
  • Compare the retention period in the register with the oldest recording still on the recorder
  • Ask three operatives from three different employers what the cameras are used for, and compare the answers with the notice
  • Check whether the JV agreement or the subcontract says anything about who decides purposes for shared site systems

Anti-pattern · One corporate DPIA for every site

The efficient-looking move is to write the assessment once and reuse it across the portfolio. It fails for a reason peculiar to projects: no two sites have the same population, neighbours, layout or supplier configuration, and it is precisely those variables that the assessment is meant to weigh. A template is genuinely useful — the standing risks, the standard mitigations, the model wording — but the site-specific pages are the assessment. Reusing them is how a contractor ends up holding a well-written document about a project that does not exist.

What holds you here

The register and DPIA describe the company, not this project, and nothing in the site systems enforces what they claim.

Highest-leverage next move

Take the highest-risk system on one live project — usually the camera estate with analytics — and make the paperwork true in the equipment: purpose, configuration, retention, access.

Cost of leaving

Effort
3–6 months
Team
Privacy lead, project data lead and the site systems supplier, with the project director sponsoring
Risk
Medium — enforcing retention and reconfiguring analytics touches live site systems for the first time
To next stage
3–6 months

If this is you, the next step is

We take one live site and make the register describe reality — retention set in the system, analytics configured to the purpose, notices workers can understand.

Make the paperwork true on one project

Stage 3

Controlled

22% of operators sit here

Controls are enforced in the site systems themselves: assessments precede energisation, models run on the narrowest useful data, and retention is set where the footage lives.

Controlled is the stage where governance moves off the shared drive and into the equipment. Retention becomes a setting on the recorder that someone verified, not a sentence in a policy. Minimisation becomes a camera angle, a masked region over the neighbouring balconies, a model that emits 'zone breach, gate 3' rather than a named person. The assessment becomes a gate in site set-up, sitting alongside the temporary works check and the utilities search — the two disciplines a construction team already respects because neither can be skipped.

The character of the work changes accordingly. Stage 2 problems are documentary; stage 3 problems are engineering and procurement: how to run PPE detection at the edge so identifiable frames never leave the site, how to give the safety team the ten seconds around an alert without giving the commercial team a searchable archive, how to configure a turnstile so that the card path and the biometric path are equally easy. None of this is exotic. All of it has to be specified before the package is let, which is why stage 3 is really a procurement capability.

The constraint that emerges is proof across the chain. The controls are real, but the evidence is scattered between a site file, a supplier's portal and someone's inbox — and the chain question is still open. The JV agreement is silent, the subcontracts say 'comply with data protection law' and nothing else, and no one has written down who decided that the exclusion-zone model should exist. The project is compliant in substance and cannot demonstrate it quickly, which in front of a client's auditor or a union representative is uncomfortably close to not being compliant at all.

In practice

The exclusion-zone alert that never named anyone

On a rail possession, a contractor runs computer vision on the existing camera estate to detect people entering the exclusion zone around a plant movement. The model emits an event with the zone, the time and a low-resolution crop; the supervisor's phone shows the zone, not a face. Identity is only resolved if the event becomes an incident, through a documented request that two named people can make and that is logged. The safety benefit is unchanged. The intrusion — and the paperwork it would otherwise require — is a fraction of what a face-searchable archive would have created.

What it looks like

  • No camera or reader is energised on site until its assessment is signed and its retention is configured
  • Vision models raise zone and PPE events without publishing identity by default
  • Biometric access has a genuine, offered alternative and workers know it exists
  • Drone and 360 capture runs to a published flight plan with notice to workers and neighbours

Diagnostic signals you can check this week

  • Ask to see the retention setting on the recorder, then check the timestamp of the oldest file actually stored
  • Ask the supervisor how they receive an alert; if the default view names a person, minimisation has not been designed
  • Ask a new starter to show you the non-biometric route through the turnstile and time it
  • Ask an engineer to point at the control behind any mitigation in the DPIA — at stage 3 they can, on site

Anti-pattern · Letting the safety camera become the productivity camera

Once the estate exists, the requests start: use the exclusion-zone footage to settle a delay claim, run the PPE model over last month to rank subcontractors, check who was on the deck at 14:00 for a disciplinary. Each is individually reasonable and collectively fatal, because the lawful basis, the assessment and the notice all described safety. Purpose creep is the single most common way a well-built stage-3 site drops back to stage 2 — and it is documented in the request log, which is exactly where a regulator or a union will look first.

What holds you here

Controls are real but the chain is undocumented — nobody has written down who decides purposes across the JV and the subcontract chain, or how to prove any of it quickly.

Highest-leverage next move

Write the controller allocation down: an Article 26 arrangement for the shared systems, flow-down terms in the subcontracts, and one project evidence pack that a client auditor can read.

Cost of leaving

Effort
4–8 months
Team
Privacy lead, project data lead, site systems supplier, and the commercial manager who lets the packages
Risk
Medium — the evidence work touches every subcontract and the JV agreement
To next stage
4–8 months

If this is you, the next step is

We build the project evidence pack from the controls you already run: DPIA register, purpose log, retention proof, chain allocation.

Turn site controls into evidence

Stage 4

Evidenced

9% of operators sit here

The project can prove it: a live register, assessments tied to site changes, a written joint-controller arrangement, consultation records and an agreed handover data schedule.

Evidenced is the stage most contractors believe they have reached and few actually have. The distinguishing property is speed of proof on the project, not at head office. A client's auditor asks who can watch the gate camera and gets a role list the same afternoon. A union representative asks what changed when the PPE model was updated and gets the assessment delta. A worker asks what the site holds about them and gets an answer inside the statutory month, including the access logs held by the turnstile supplier, because somebody mapped that relationship when the package was let.

The economics invert here, and on projects the effect is unusually direct. Below this stage every external question is a fire drill that pulls the project team off the programme. At stage 4 the marginal cost of answering approaches zero, and the evidence starts winning work: public-sector and regulated clients increasingly score data-handling posture in prequalification, framework renewals ask for it, and a contractor that can hand over an information model with a clean personal-data position is a contractor whose client's own compliance team stops treating handover as a risk.

What still limits stage 4 is that the discipline lives with the project team rather than in the operating model. The next bid team writes it from scratch, the next JV negotiates the arrangement from first principles, and the subcontract flow-down depends on which commercial manager drafts the package. Meanwhile the EU AI Act's obligations for AI used to monitor and evaluate workers arrive on top of the GDPR work, and a project-by-project posture meets them project by project. The move to stage 5 is making governance part of how the business wins and closes work, not part of how one team runs one site.

In practice

The client audit answered from the site office

Six months into a two-year infrastructure package, the client's information governance team runs an audit on the JV. They ask for the camera register, the assessment for the plant-proximity system, the list of people who can retrieve footage, and the retention configuration. The JV's project data lead answers all four from the site office within a day, and produces the joint-controller arrangement from the JV deed when asked who decided the purposes. The audit closes with two observations and no actions. The same client's previous audit of the same contractor, three years earlier, ran for eleven weeks.

What it looks like

  • A project-level register that names every system, purpose, holder and retention period
  • An Article 26 arrangement in the JV deed, with a single published contact point for data subjects
  • Assessment review triggered by site change — new package, new supplier, new analytics module
  • The handover data schedule was agreed at contract award, not discovered at practical completion

Diagnostic signals you can check this week

  • Ask for the project register and check its last-updated date against the last package let on site
  • Ask who the published contact point is for a worker's data question, and whether subcontractors' operatives know it
  • Run a dry access request covering the turnstile supplier's records as well as your own systems
  • Ask when the handover data schedule was agreed; 'at award' is stage 4, 'we will sort it at PC' is not

Anti-pattern · Evidence that lives at head office

The registers are immaculate, the assessments are filed, the policies are versioned — and all of it sits on the corporate intranet, two organisational layers away from the site that generates the data. When the question arrives it arrives on the project: a neighbour at the gate, a union representative in the canteen, a client's auditor in the site office. If the answer requires an email to head office and a two-day wait, the project is running stage-3 evidence with stage-4 filing. Put the pack where the site is, and make the project team its owner.

What holds you here

Governance is provable on this project but not built into how work is won, let and closed — and AI Act obligations for worker-monitoring systems are arriving on top.

Highest-leverage next move

Push the artefacts upstream and downstream: prequalification questions, standard JV arrangement, subcontract flow-down clauses, and a priced handover data schedule in every contract.

Cost of leaving

Effort
6–12 months
Team
Privacy lead embedded with the project, commercial lead for flow-down, JV partner counterparts, union or works-council liaison
Risk
Medium — the work is operating rhythm and contract drafting more than build, and rhythms are harder to ship
To next stage
6–12 months

If this is you, the next step is

We turn one project's evidence pack into the standard set your next bid, JV and site set-up inherit automatically.

Make the evidence travel with the project

Stage 5

Trusted

4% of operators sit here

Governance travels with the work: it is asked for at prequalification, flowed down in subcontracts, and closed out at handover as a priced, certified deliverable.

Trusted is narrower and more operational than the word suggests. It does not mean a contractor is admired; it means the governance system is credible enough that the parties around the project extend it the benefit of the doubt, and the project team stops routing around it. Clients accept the handover pack instead of commissioning their own review. Union representatives start from 'show us what changed' rather than from opposition. Site managers reach for the standard camera specification because it is the paved road, not because someone will check. The system has become cheaper to follow than to bypass, which is the only condition under which governance survives a programme squeeze.

The EU AI Act is the proving ground for this stage. AI used for monitoring and evaluating workers sits in the regulation's high-risk category, which brings risk management, logging, data-quality, transparency and human-oversight obligations for deployers on a statutory timetable, and the workplace prohibitions — notably inferring emotions at work — apply regardless of risk class. A trusted contractor meets most of this from the evidence it already generates: the DPIA extends to a fundamental-rights view, the alert logs exist, the oversight roles are named in the safety management system. Contractors below stage 4 will experience the same deadlines as a second, parallel compliance programme running against the same programme dates.

Sustaining stage 5 is a change-management discipline and this is where regression starts. Every project is a new organisation with a new population, a new supply chain and a new client. A framework renewal brings a supplier whose analytics defaults differ. An acquisition brings sites nobody has walked. A new client demands person-level dashboards the current design deliberately cannot produce. Each is small; each invalidates an assessment somewhere. The stage-5 contractor ties governance review to project events — site set-up, package award, supplier change, model update, handover — rather than to the calendar, and treats a governance regression with the seriousness of a safety observation.

In practice

The handover that included a deletion certificate

At practical completion on a data-centre project, the contractor hands over the information model, the health and safety file and a two-page data schedule: what personal data travels to the client and why, what stays with the contractor under statutory retention, and what has been destroyed — with a certificate from the systems supplier covering the camera archive and the biometric templates, dated the week after the final snagging visit. The client's compliance team signs it off in a day, and asks whether the same schedule can be added to the framework's standard particulars.

What it looks like

  • Data-handling posture is cited in won bids and framework renewals, not only in audits
  • Every subcontract carries flow-down terms on capture, retention and deletion that suppliers actually price
  • Union and works-council engagement on new site monitoring is measured in weeks and recorded
  • Handover includes a data schedule, a transfer list and deletion certificates for what does not travel

Diagnostic signals you can check this week

  • Look for data-handling posture cited in bid documents and framework returns, not just audit responses
  • Time the last consultation on a new monitoring system with union or works-council representatives
  • Check whether the last three subcontract packages carried priced flow-down terms on capture and deletion
  • Ask to see the most recent handover data schedule and the deletion certificates behind it

Anti-pattern · Treating handover as the end

The certificate is signed, the project team demobilises, and everyone assumes the personal-data question closed with it. It did not: the client now holds an information model that may contain identifiable site imagery, the systems supplier may still hold an archive under its own retention default, and the contractor keeps statutory records for years. Each of those is a live processing operation with a controller, and the day the project team disbanded is the day nobody owned any of them. Close the loop deliberately — named owner, stated period, evidence — or the archive outlives everyone who understood it.

What holds you here

Sustaining trust is change management across a portfolio of temporary organisations: every new project, supplier, model update and client can silently invalidate an assessment.

Highest-leverage next move

Wire governance review to project events — site set-up, package award, supplier change, model update, handover — and rehearse the awkward scenarios before they arrive unannounced.

Cost of leaving

Effort
Continuous
Team
Privacy lead inside the delivery business, bid and commercial teams, standing supplier assurance, workforce representatives
Risk
Concentrated — low frequency, high consequence; the cost of failure is client trust and workforce consent, neither of which rebuilds on a programme timescale

If this is you, the next step is

We run a scenario — worker access request, union challenge, client audit, AI Act query — against one live site and report where it creaks.

Stress-test the system on a live project

Where construction and infrastructure projects actually sit

The distribution across the ladder, why Inventoried is the plateau on projects specifically, and the two dimensions that drag the average down.

Most projects sit at Inventoried: the corporate paperwork exists and the site runs ahead of it. That gap is structural rather than cultural. Governance artefacts are written by a permanent organisation at head office, while the data is created by a temporary organisation on site that was assembled six months ago, buys its own kit under programme pressure, and will be dissolved before anyone reviews the register. The distribution below is illustrative — it synthesises regulator guidance on workplace monitoring rather than reporting a measured survey — but the shape is the one every auditor recognises.

Where projects sit on the data-governance ladder

Illustrative distribution across the five stages, synthesised from ICO employment-monitoring and video-surveillance guidance — not a measured survey. Inventoried is the plateau: the register exists, and nothing on site enforces it. The share that can prove its position quickly is small, which is why evidence has become a prequalification asset rather than an audit chore.

Share of projects (illustrative)

  • 27% — 1 · Unmapped
  • 38% — 2 · Inventoried (the plateau)
  • 22% — 3 · Controlled
  • 9% — 4 · Evidenced
  • 4% — 5 · Trusted

Source: Illustrative, synthesised from ICO guidance on monitoring workers

Two of the four dimensions do most of the damage. Controller roles across the chain is the lowest-scoring dimension on almost every joint venture, because the question is genuinely hard and nobody owns it: the JV deed is drafted by commercial lawyers around risk and profit share, the site systems are specified by a delivery team, and the moment where those two conversations should have met never appears in anyone's programme. Retention and handover is the second, and it fails for a simpler reason — the person who would have to act is demobilised by the time the question becomes urgent.

The dimensions are not independent. A project that scores well on inventory and badly on chain roles is holding a precise description of processing it cannot allocate; a project with strong controls and no handover schedule is running a clean site that will leave an unowned archive behind it. The assessment scores all four separately for that reason, and in practice the lowest one sets the stage — the same way the weakest temporary works detail sets the load a structure can actually carry.

Where personal data is created on a site

Eight site systems most project teams treat as operational kit, the personal data inside each, whose data it actually is, and the basis that survives scrutiny.

Personal data is created on a site wherever a device can be joined to a person, and on a construction project almost everything can. The join is one hop away and it is always the same hop: the induction record, which ties a card, a face or a tag to a named individual and an employer before that individual is allowed past the gate. GDPR does not care that the camera was bought to deter theft or that the tag was bought to keep people away from a slew radius. If a person is identifiable from the data plus reasonably available means, the system is processing personal data and needs a purpose, a basis, a retention limit and a place in the register. The table below maps the eight systems that carry most of the risk on a modern site.

Site systemPersonal data inside itWhose data it isBasis that usually survivesThe project watch-out
Site CCTV with computer visionContinuous imagery of everyone in frame, plus structured events: PPE state, zone entry, plant proximity, time and locationEvery worker on site whoever employs them, visitors, and passers-by at the boundaryLegitimate interests with a documented LIA, safety stated as the specific interestAn analytics module switched on by a supplier update is a new purpose; boundary cameras routinely see the public footpath
Biometric turnstiles and access controlFacial or fingerprint templates processed to identify a specific individualOperatives of every employer on site, including agency and short-duration labourAn Article 9 condition on top of an Article 6 basis — which is why most projects should use cards or fobs'The client asked for it' is not necessity; the non-biometric route must be real, offered and equally quick
Access cards, inductions and competence recordsName, employer, competence card, photograph, right-to-work evidence, in and out timesEvery inducted person, held by the principal contractor for the whole chainLegal obligation for statutory duties; legitimate interests or contract for the restAttendance records drift into productivity and disciplinary use; some jurisdictions compel presence registration
Wearables and proximity tagsPosition within the site, proximity and near-miss events, sometimes physiological or fatigue signalsOperatives wearing them — frequently employed by a subcontractor, not by the tag's buyerLegitimate interests with an LIA; an Article 9 condition if health signals are processedContinuous individual location is far more intrusive than a zone breach; welfare and rest areas must be excluded at source
Drone and 360-camera captureImagery of workers, plant, neighbouring properties, gardens, windows, vehicles and people beyond the boundaryWorkers, neighbours and the public, none of whom were inductedLegitimate interests for progress and survey purposes; aviation rules apply separately and do not substituteIncidental capture past the red line, and progress imagery published to social media without a second look
Site photographs and defect records in the CDEFaces, number plates, tattoos and workers identifiable by task, embedded in quality and progress recordsWorkers and subcontractors, indexed against packages and datesLegitimate interests for the record; contract where the imagery is a deliverableThis is the class most likely to be handed to the client and kept for the life of the asset
Plant telematics and operator identificationMachine utilisation and event data linked to an operator through a key card or licence checkOperators, usually employed by a plant supplier rather than the contractorLegal obligation for competence checks; legitimate interests for utilisation and maintenanceThe plant supplier is a controller in its own right, so the operator has two organisations watching one seat
Model training corpora built from site imageryEverything above, frozen at the moment of capture and retained to retrain modelsEveryone the site ever captured, including people who left years earlierCompatibility with the original purpose under Article 6(4), or a fresh basis of its own'We already have the footage' is not a basis, and corpora outlive both the project and the conversation that justified them
The eight personal-data systems in a typical construction or infrastructure project. 'Whose data' is the column project teams underestimate: on a site, most of the people in the data are employed by somebody else.

Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.

Purpose limitation is the principle that does the heavy lifting on a site, because site systems are unusually easy to repurpose. The estate is already installed, the footage is already retained, and every new question — who was on the deck, which gang was slow, who left the gate open — can be answered from data collected for safety or security. The EDPB's guidelines on video devices (opens in a new tab), the ICO's video surveillance guidance (opens in a new tab) and the Article 29 Working Party's Opinion 2/2017 on data processing at work (opens in a new tab) all approach workplace monitoring the same way: the question is never whether monitoring is allowed in principle, but whether this specific processing, at this granularity, for this purpose, is proportionate to what it achieves — and whether the people in the data were told.

  • The special-category corners a site walks into without noticing

    Biometric identification at the turnstile, health and fitness-to-work data from occupational health or fatigue wearables, and drug and alcohol testing all sit under Article 9 (opens in a new tab), which requires a separate condition on top of the ordinary basis — the ICO's biometric recognition guidance (opens in a new tab) sets out how narrow those conditions are in practice. So does anything that reveals trade-union membership — and monitoring that records who attended a consultation meeting, or which operatives a union representative spoke to, does exactly that. Given the industry's own history, this is the corner to be most careful in.

  • Neighbours and the public are data subjects too

    A boundary camera that sees the footpath, a drone that overflies gardens, a 360 walk that captures a neighbouring office through a window: none of these people were inducted, none received a notice at the gate, and all of them are identifiable. Aim and mask at installation, plan flight lines to the red line, and treat imagery beyond the boundary as a defect to be fixed rather than a by-product to be filed. Flight rules from the UK Civil Aviation Authority (opens in a new tab) and EASA (opens in a new tab) govern the flying; they say nothing about the recording, and complying with one is routinely mistaken for complying with the other.

  • Agency and short-duration labour is where transparency fails

    An operative on site for three days through an agency receives the induction, signs for the PPE and passes through the turnstile like everyone else — and is the least likely person on site to have read anything about the monitoring. Transparency has to work at the gate, in the languages actually spoken on the project, in a form someone can absorb in the two minutes they will give it. A privacy notice that only exists inside a 60-page induction pack is a notice for the auditor, not for the worker.

  • Statutory presence registration is a live example of a legal obligation basis

    In Belgium, contractors on construction works above a statutory value threshold must make a declaration of works and register the daily presence of everyone performing the work, through the federal checkinatwork formalities (opens in a new tab). Where a rule like this applies, the basis for collecting who was on site and when is settled by law — and the interesting governance question becomes what else the project does with the same records once it holds them.

One principle organises the whole map: a site event is personal data whenever it can be traced to one human, and genuinely anonymous the moment it cannot. That boundary is an engineering artefact — where the induction join sits, who can perform it, whether the model emits a zone or a face, what the aggregate suppresses — which is why data governance on a project is a design and procurement discipline first, and a documentation discipline second. Everything the register records was decided when a package was let.

When a site system needs a DPIA, and where the AI Act lands

Site monitoring meets the Article 35 triggers several times over — and the same systems are the ones the EU AI Act treats as high-risk worker management.

A DPIA is required before a site monitoring system goes live whenever the processing is likely to be high risk, and computer-vision site monitoring clears that bar several times over: it is systematic monitoring of individuals, it happens in a workplace where the people in the data are in a dependent position, it uses innovative technology, and on a large project it operates at scale. Article 35 (opens in a new tab) sets the duty and the ICO's DPIA guidance (opens in a new tab) operationalises it as a screening list — as a working rule, two or more triggers means run the assessment. The trap on projects is timing rather than judgement: the assessment has to be finished before the system is energised, and site set-up moves faster than any governance process that is not part of it.

None of this is an argument against monitoring. Construction remains one of the most dangerous sectors to work in, and the Health and Safety Executive's construction pages (opens in a new tab) set out why exclusion zones, plant separation and PPE discipline are enforced the way they are: the hazards that computer vision is pointed at are the ones that kill people. A DPIA is not a hurdle placed in front of that. It is the document in which a contractor writes down that the safety purpose is real, that the design collects the least it can while still achieving it, and that somebody accountable weighed the intrusion — which is exactly the argument a project will want on file the first time a union representative, a client or a regulator asks why the cameras are there.

DPIA trigger check for a site system

Tick every condition that applies to the system you have in mind — the CV camera estate, the turnstile, the proximity tags, the weekly drone flight. Two or more ticks means run the DPIA before energisation; the note below tells you what your tally usually implies on a project. Works without JavaScript.

0 of 6 ticked

0 ticked — check you assessed the right system

Almost nothing on a modern site scores zero: a camera estate with any analytics, a turnstile, or a proximity tag will trip at least one condition. If your honest count really is zero — say, a fixed progress camera on a time-lapse with no people visible at that resolution — record the screening anyway. The note that you assessed and found no high risk is itself the accountability artefact a regulator expects to see.

The EU AI Act arrives on top of GDPR rather than instead of it, and it lands on precisely the systems this page is about. The AI Act (opens in a new tab) classifies AI intended to monitor and evaluate the performance and behaviour of people at work as high-risk, which captures PPE and behaviour analytics, productivity inference from access and plant data, and any allocation model that decides who works where. It also prohibits outright the use of AI to infer emotions in the workplace, which rules out the fatigue-and-mood inference some site camera products advertise. Deployer duties are the ones a contractor feels: competent human oversight, input data that is relevant for the purpose, retention of the system's logs, and — the duty most likely to catch a project unaware — informing workers' representatives and affected workers before a high-risk system is put into service at the workplace. The European Commission's AI Act pages (opens in a new tab) track the phased application dates.

Worker consultation is the other duty that arrives from several directions at once, and on a project it is also the cheapest evidence available. Article 88 (opens in a new tab) lets member states set their own rules for processing in the employment context, including through collective agreements, so the applicable standard on a site in Berlin is not the standard on a site in Birmingham. EU law on informing and consulting employees (opens in a new tab) applies on top, and in Germany the Works Constitution Act (opens in a new tab) gives works councils co-determination rights over technical devices capable of monitoring workers — which in practice means agreement before installation, not notification afterwards. On a multinational JV these regimes stack, and the population on site may include posted workers whose home-state representatives also have standing. Consult early, record what changed as a result, and attach the record to the assessment: a balancing test with the workforce's fingerprints on it survives challenge, and one written alone in a legal team rarely does.

Site systemDPIA positionAI Act positionWhat the deployer has to do on site
CV cameras: PPE and exclusion-zone alertingRequired — systematic monitoring of workers at scaleHigh-risk worker monitoring where output evaluates behaviourNamed oversight role, alert log retained, workers and their representatives informed before go-live
Biometric turnstileRequired — biometric identification plus dependent data subjectsBiometric categorisation and remote identification are tightly restricted; workplace deployment needs careArticle 9 condition, an offered non-biometric route, template retention limited to the site duration
Wearables and proximity tagsRequired where individuals are identifiable and tracked continuouslyHigh-risk if the output is used to evaluate the person rather than to warn themZone-level rather than person-level output by default, welfare areas excluded, health signals separately justified
Drone and 360 progress captureUsually required — large-scale imagery including people who were never informedNot automatically high-risk; becomes so if the imagery drives worker evaluationPublished flight plan and notice, boundary masking, review before any external publication
Allocation or scheduling models using worker dataRequired — evaluation with effects on individualsSquarely inside the employment and workers-management categoryHuman decision documented, Article 22 analysis, contestation route the workforce actually knows about
Progress and quality imagery in the CDEScreening record at minimum; required if faces are searchableNot high-risk in itself; training a behaviour model on it changes thatRedaction rules before handover, and terms saying whether a supplier may train on the imagery
How the two regimes land on the systems a site actually runs. 'Deployer duty' is what the contractor must do; the provider's obligations sit with the vendor, and buying from a compliant vendor does not discharge yours.

The EDPB's Opinion 28/2024 on AI models (opens in a new tab) closes the loop on the corpus question that site DPIAs now have to answer. Personal data inside a training pipeline remains personal data; a claim that a trained model is anonymous is something to demonstrate rather than assume; and a model trained on unlawfully collected material is not cleansed by the training process. For a contractor whose supplier proposes to improve its PPE detector on four years of your site footage, that has a concrete consequence: the reuse needs its own compatibility analysis or its own basis, and the answer belongs in the contract before the first camera is commissioned, not in a renewal negotiation afterwards. The ICO's guidance on AI and data protection (opens in a new tab) sets out the same expectations for UK projects.

What enforcement and precedent look like in construction

Three publicly documented cases about workers' data in and around construction sites, read against the ladder. Each links to the regulator's or the public body's own material.

Regulators have already ruled on the exact data patterns site monitoring is built from — worker records shared across a contractor chain, biometric identification used to control access to work, and statutory registration of who is on site. None of the three cases below punishes monitoring in principle. Each turns on the governance around it: whether anyone could account for the data, whether a less intrusive method was available, and whether the purpose the data was collected for is the purpose it is used for. That distinction is the whole argument of this page, and it is worth reading in the regulators' own words rather than in a summary.

Three cases read against the ladder

Findings and figures as published by the regulators and public bodies themselves. Stage placements are our editorial reading against the project governance ladder, not the regulator's language. The photographs are industry scenes from our image library, not photographs of the organisations named — none of these is an Atomic Loops engagement.

Scene: a construction site team reviewing worker data records on a tablet, with a privacy shield graphic on the hoarding behind themThe Consulting AssociationUK construction chain · ICO investigation and prosecution, from 200911
Challenge
Worker information moved between construction firms through a third party with no accountability attached to it. As the ICO records, the organisation kept indexes on thousands of construction workers — often union members or workers who had raised health and safety concerns — including names, addresses, press cuttings and character assessments.
Approach
Firms checked the names of prospective workers against the database before engaging them, so a record created by one company determined whether a person could work for another. The ICO investigated after raiding the organisation's offices in February 2009.
Reported outcome
The ICO forced the organisation to shut down and prosecuted its operator, then made details of the database available to the people on it, which supported later legal action; in 2016 trade unions settled with construction firms in a compensation package the ICO describes as worth millions of pounds.
What it shows about the curveThis is the Unmapped stage at its most consequential: worker data crossing company boundaries on a project, with no register, no basis and no allocated controller. The systems have changed — the shared database is now a shared site platform — and the structural question has not.

ICO — construction employment deny list (opens in a new tab)

Scene: a monitoring camera on a mast overlooking a live construction site, with a supervisor reviewing detections on a screenSerco Leisure and associated trustsWorkplace attendance monitoring · ICO enforcement notices, February 202423
Challenge
Facial recognition and fingerprint scanning were used to check the attendance of more than 2,000 employees across 38 leisure facilities, and to pay them for their time. Biometric identification of a workforce for attendance is the same pattern as a biometric site turnstile, which is why the decision reads directly across to construction.
Approach
The ICO assessed necessity and proportionality rather than banning biometric technology: it found the organisations had failed to show why facial recognition and fingerprint scanning were necessary or proportionate for attendance checking when less intrusive means such as ID cards or fobs were available, and that employees had not been proactively offered an alternative.
Reported outcome
Enforcement notices required the organisations to stop all processing of biometric data for attendance monitoring and to destroy the biometric data they are not legally obliged to retain, within three months of the notices being issued.
What it shows about the curveThe lesson for a site gate is precise: the question is never whether biometrics work, it is whether you can show a card would not. 'Faster throughput at shift change' is an argument that has to be evidenced, and an alternative route has to be genuinely offered, not merely available on request.

ICO — enforcement action, Serco Leisure Operating Limited and associated trusts (opens in a new tab)

Scene: operatives on a live construction site with a supervisor logging presence and safety data on a tablet, drone overheadBelgian federal presence registrationStatutory site-presence registration · Belgium, FPS Employment34
Challenge
Belgium requires contractors performing construction works above a statutory value threshold to make a declaration of works and to register, daily, the presence of the people carrying out the work — including subcontractors and self-employed workers in the chain.
Approach
Registration runs through federal services rather than through each contractor's own system, so the purpose, the data set and the recipients are fixed by law instead of being decided package by package on site.
Reported outcome
The formalities are published by the Federal Public Service Employment, Labour and Social Dialogue, which sets out the declaration and presence-registration duties that apply to construction works and to posted workers in the chain.
What it shows about the curveWhere a legal obligation applies, the basis for knowing who was on site is settled and the governance question moves on: what else does the project do with the same records? Attendance data collected under a statutory duty does not carry a licence to run productivity analytics on it — that is a different purpose needing its own basis and its own assessment.

FPS Employment, Labour and Social Dialogue (Belgium) — construction formalities (opens in a new tab)

Read together, the three describe the same fault line from different sides. The first is what happens when worker data crosses company boundaries with nobody accountable for it — the failure mode a construction project reproduces every time six firms share one system with no written allocation. The second is a regulator applying the necessity test to a technology choice and finding the cheaper, duller option adequate. The third is a reminder that some site data collection is compelled, which settles the basis and sharpens the purpose-limitation question rather than removing it. None of the three is about AI, and all three are about the governance an AI system inherits the moment it is pointed at a workforce.

Who is the controller when six companies share one site

Roles follow function, not the label in the subcontract — and on a joint venture the joint-controller question is answered whether or not anybody writes it down.

The controller is whoever decides why and how personal data is processed, which on a project is rarely the company whose logo is on the camera. A principal contractor that specifies an exclusion-zone model, chooses its coverage and sets its retention is the controller for that processing even though the footage sits on a supplier's platform and the subcontractors' operatives are the people in it. A subcontractor that pulls the same footage into its own safety programme has become a controller for that new purpose. And where a JV board or a project board decides together that the system should exist, the partners are joint controllers under Article 26 (opens in a new tab) — a status that arises from the facts, not from a clause. The EDPB's guidelines on controller and processor (opens in a new tab) are explicit that the analysis is functional: a contract calling everyone a processor does not survive contact with who actually set the purpose.

Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers.

Party on the projectSite CCTV and CV monitoringBiometric or card access controlThe project wrinkle
Client / employerNo role — unless it mandates the system, its coverage or its reporting, which makes it a controller for that purposeController for anything it specifies, including 'all operatives to be biometrically enrolled'A client requirement written into the works information is a purpose the client decided; it cannot then be a bystander
Principal contractorController — it specifies coverage, analytics, retention and who may retrieve footageController for site access; also the party that holds the induction join for the whole chainIt controls data about thousands of people it does not employ, and must be reachable by all of them
JV partnersJoint controllers where the board decided the system, however the deed allocates profit and riskJoint controllers for the gate; the arrangement must say who answers a workerUndocumented joint control means each partner carries the whole obligation, and the workforce has no single door to knock on
SubcontractorRecipient of alerts; controller the moment it reuses footage for its own safety, disciplinary or claims purposesController for its own employees' records; recipient of site access dataIts own drone, camera or app is processing nobody registered, on a site it does not control
Labour agency / umbrellaNo role in the estate; controller for its own workers' employment recordsController for the credentials it issues and the hours it billsIts workers are the least informed population on site and the most likely to be missed by a notice
Camera, CV or access supplierProcessor — until it reuses site imagery to improve its own detection modelsProcessor for enrolment and matching; holds templates on its own infrastructureModel-improvement reuse flips it to controller for that purpose; the Article 28 terms must address derived data in terms
Surveyor / designer capturing imageryController for its own survey purposes; recipient where it receives project imageryNo role, unless it is given access records for programme analysisSurvey capture is scoped as a deliverable, so nobody treats the incidental people in the imagery as a processing question
Role allocation for the three systems that cause most of the argument on a project. The last column is the wrinkle that turns a stable twenty-year contractual relationship into an unexamined processing decision.

Which allocation applies to a shared site system

Place each shared system by who decided its purpose and who acts on its output. Most disputes on projects come from the top row, where several companies use a system nobody agreed to own.

Controller with recipients

  • Principal contractor specified it; subcontractors get logins
  • They are recipients, not processors — say so in writing
  • Terms must state what a recipient may do with what it sees

Joint controllers — Article 26 applies

  • JV or project board decided the system exists
  • Arrangement must allocate transparency, rights and breach duties
  • Publish one contact point the workforce can actually use

Controller and processor

  • One contractor decided; the supplier runs it on instructions
  • Article 28 terms carry the relationship
  • Watch the clause on derived data and model training

Imposed purpose, delegated operation

  • Client mandated it; one contractor operates it
  • The client is a controller for the purpose it imposed
  • Do not accept a processor label for a decision you did not make
Who acts on the output — top: Several across the chain read and act, bottom: One organisation reads it
Who decided the purpose — left: One organisation decided alone, right: Two or more decided together

Writing the joint-controller arrangement into a JV

  1. List purposes, not systems

    Start from what the project is trying to achieve — deter theft at the gate, keep people out of a slew radius, prove who was inducted, evidence progress for payment — and attach systems to purposes rather than the other way round. Purposes are what the regulation allocates, and a purpose list survives the supplier change that a system list does not.

  2. Allocate the duties that have to have an owner

    Transparency to the workforce, responding to access and objection requests, security of the estate, breach notification, retention and deletion, and the DPIA itself. Article 26 lets partners allocate these between them, but it does not let them disappear: whatever the arrangement says, a worker can exercise their rights against any joint controller, so the internal allocation is about who does the work rather than who is exposed.

  3. Publish one contact point at the gate

    The essence of the arrangement must be available to the people in the data, and on a project that means the gate, the induction and the site notice board — not a corporate privacy page belonging to whichever partner drew the short straw. One email address, one named role, answered inside the statutory month, for every one of the several thousand people who pass through the turnstile.

  4. Flow it down, and price it

    Subcontract terms should state what capture a subcontractor may bring, what it may do with anything it receives, how long it may keep it, and what happens at completion — with deletion evidence as a condition of final payment. A flow-down clause nobody priced is a clause nobody will comply with when the programme tightens.

The supplier relationship deserves its own scrutiny, because it is where the modern failure mode lives. A camera, CV or access vendor is a processor under Article 28 (opens in a new tab) while it acts on your instructions — and stops being one the moment it uses your site imagery to improve its own detection models, benchmark across customers or build a product it sells back to the industry. That is its own purpose, decided by it, which makes it a controller for that processing while you remain accountable for having routed the data there. Contracts written before analytics arrived rarely say anything about derived data, aggregate statistics or training corpora. Every renewal is the cheap moment to fix that; the expensive alternative is discovering the answer in a client's audit or a worker's access request.

What happens to four years of site data at handover

At practical completion the project stops existing and its archives do not. Every class needs one of three answers — deleted, anonymised, or transferred with a stated basis and a named owner.

At handover, the personal data a project created has to be deleted, anonymised or transferred to a named party on a stated basis — and if nobody decides, the default is the worst of all worlds: an archive that survives with no controller, no purpose and no owner who knows it exists. This is the question that separates project data governance from every other industry's version of the same problem. A factory's monitoring belongs to the factory for as long as the factory exists. A project's monitoring belongs to an organisation that dissolves on a known date, in front of a client who is inheriting an asset and would rather not inherit a liability with it.

Data classWhy it existsWhat sets the retentionDefault at practical completionWho may inherit it
Raw camera footageDeterrence, incident investigation, dispute evidenceThe longest live investigation window — weeks, not yearsDelete, with evidence from whoever holds the storageNobody; extracts tied to a live incident travel separately and are listed
CV detections and alert recordsSafety intervention at the time, trend analysis afterwardsThe safety management system's own record period; trends do not need identityAggregate to zone and period, delete the identified layerThe contractor's safety function, in aggregate form
Biometric templatesVerifying identity at the gateThe site duration — there is no purpose after the last shiftDestroy at demobilisation, evidenced by certificateNobody, in any circumstances
Access and turnstile logsPresence, evacuation roll call, payment verification, right-to-work checksThe statutory duty that compelled each field — employment, tax, immigration, safetyKeep only the fields a named duty requires; delete the restEach employer for its own people; the contractor for its own statutory records
Wearable and proximity eventsCollision avoidance in the moment, near-miss learning afterwardsThe near-miss reporting cycle, not the length of the projectAggregate and delete the individual layerThe tag or plant supplier only where contracted and evidenced
Drone and 360 imageryProgress, survey, measurement, claims evidenceThe defects liability period and the limitation period for claimsRedact people, then transfer where it is a contractual deliverableClient or asset owner, under the information requirements
Site photographs in the CDEQuality records, as-built evidence, claims defenceLimitation period, plus the asset's own information requirementsReview for identifiable people, redact what the record does not need, then transferClient or asset owner
Health and safety file, and the golden threadStatutory duty to the client and, for higher-risk buildings, the accountable personThe life of the assetHand over — it is a statutory and contractual deliverable, not an optionClient, and the accountable person for higher-risk buildings
Model training corpora from site imageryImproving a supplier's or the contractor's own detection modelsThe compatibility analysis or fresh basis, if either was ever doneDelete unless documented terms and a basis cover the retentionOnly a party named in those terms, for the purpose they state
Disposal positions by data class at practical completion. 'What sets the retention' is the honest driver — usually a statutory duty or a claims window, almost never the length of the project.

Two statutory duties cut across the table and are routinely used to justify keeping everything, which is precisely backwards. Under CDM 2015 (opens in a new tab) the health and safety file must be passed to the client at the end of the project and kept available for those who need it — but the file is a defined set of information about residual risks in the asset, not an archive of who was on site. For higher-risk buildings, the golden thread (opens in a new tab) must be kept digitally and handed over, and the GOV.UK guidance itself requires that the information is managed in a way compliant with data protection law. Both duties compel the transfer of specific building information. Neither compels — or permits — the transfer of four years of camera footage, and using them as cover for a wholesale archive dump is the single most common handover mistake.

The handover disposal decision

Run every class in the register through this once, at contract award rather than at practical completion. The bottom-right quadrant is the one nobody budgets for, and it is where the site camera estate lands.

Keep, but only the duty's fields

  • Statutory employment, tax and safety records
  • Trim to what the named duty actually requires
  • Record the duty against the class in the register

Transfer with a basis and a named owner

  • Health and safety file, golden thread, as-built imagery
  • Redact what the asset record does not need
  • The receiving controller is named in the handover schedule

Keep freely — it is no longer personal data

  • Zone-level safety counts, utilisation aggregates
  • Test the anonymisation before relying on it
  • Small counts and single-operative zones are not anonymous

Delete, with evidence

  • Camera archives, biometric templates, proximity traces
  • Certificate from every holder, suppliers included
  • This is the quadrant that needs a budget line and a date
Does a duty require it after completion? — top: Statutory or contractual duty continues, bottom: No duty continues after PC
Is anyone identifiable in it? — left: No — genuinely aggregated or anonymous, right: Yes — faces, names, credentials, templates
  • Decide the destinations at award, not at completion

    On the last day of a project the people who understood the systems have demobilised, the supplier's account manager has moved on, and there is no budget left to pay for a data close-out nobody scoped. Writing the handover data schedule into the contract at award costs an afternoon and turns close-out into an invoiced task with an owner.

  • Make deletion evidence a payment condition

    A supplier asked to delete an archive after final payment has no commercial reason to prioritise it. A certificate of destruction listing the systems, the date and the volumes, made a condition of the final account, is the cheapest enforcement mechanism available on a construction contract — and it is the artefact a client's auditor will ask for two years later.

  • Check the information model before it leaves

    The model, the CDE export and the as-built imagery are the classes most likely to travel and the least likely to be examined. Faces at a work face, number plates in a compound, a whiteboard with a gang list: none of it is needed by the asset owner, all of it is personal data, and once it is inside a client's information estate it is subject to a retention policy written for buildings rather than for people. The information-management discipline already exists — ISO 19650 (opens in a new tab) and the UK BIM Framework (opens in a new tab) define how project information is produced, reviewed and handed over — so the practical move is to add a personal-data check to the acceptance criteria the CDE already enforces, rather than inventing a parallel process nobody will run.

  • Name a surviving owner for whatever must persist

    Some data legitimately outlives the project — statutory records, claims evidence, the safety file. Each needs a named organisation and role that continues to exist afterwards, recorded in the schedule. 'The project' is not an answer, and a JV that dissolves without allocating this leaves an archive whose controller has no legal personality.

The governance stack a project actually needs

Five layers, each annotated with the stage that first requires it — and defined by what it must guarantee rather than by which product provides it.

A defensible project needs five layers, and the order in which they are built decides whether governance compounds across projects or gets rebuilt on each one. The stack below is deliberately unfashionable: no layer names a vendor, and each is defined by the guarantee it has to make. Read it as a set-up checklist for a new site rather than as an architecture diagram — the first three layers are established in the first fortnight on site, and the last two are established in the contract before anybody mobilises.

The five layers, stage-annotated

Each layer is marked with the ladder stage that first requires it. A project trying to reach Controlled without the identity and record layers is running an inventory exercise with cameras attached.

  1. Site capture layer

    Stage 1+

    • Cameras and CV endpointsFraming, masking and resolution fixed at installation, not in software later
    • Access control and readersCards by default; biometrics only with an evidenced necessity case
    • Mobile and aerial captureDrones, 360 walkers and survey kit registered before the first flight
  2. Identity and transparency layer

    Stage 2+

    • Induction registerThe join between a person, an employer and a credential — held separately
    • Logged identity resolutionIdentity revealed on a recorded request, never as the default view
    • Transparency at the gateSignage, induction briefing and notices in the languages spoken on site
  3. Project record layer

    Stage 2+

    • Project registerEvery system, purpose, holder, access list and retention period on this site
    • DPIA registerOne assessment per system, reopened by site change rather than by anniversary
    • Purpose and request logWho asked for footage, for what reason, and who approved the retrieval
  4. Chain and contract layer

    Stage 3+

    • Joint-controller arrangementPurposes and duties allocated across JV partners, essence published
    • Subcontract flow-downCapture, retention, deletion, sub-processors and model training, priced
    • Supplier processing termsInstructions-only processing, and what may happen to derived data
  5. Close-out and handover layer

    Stage 4+

    • Handover data scheduleAgreed at award, priced in the close-out, executed at practical completion
    • Deletion evidenceCertificates from every holder, including suppliers and sub-processors
    • Information-model reviewPersonal data in the model identified, justified or redacted before transfer

Pipeline described

  1. Site capture layer (stage 1+) — Cameras and CV endpoints: Framing, masking and resolution fixed at installation, not in software later; Access control and readers: Cards by default; biometrics only with an evidenced necessity case; Mobile and aerial capture: Drones, 360 walkers and survey kit registered before the first flight
  2. Identity and transparency layer (stage 2+) — Induction register: The join between a person, an employer and a credential — held separately; Logged identity resolution: Identity revealed on a recorded request, never as the default view; Transparency at the gate: Signage, induction briefing and notices in the languages spoken on site
  3. Project record layer (stage 2+) — Project register: Every system, purpose, holder, access list and retention period on this site; DPIA register: One assessment per system, reopened by site change rather than by anniversary; Purpose and request log: Who asked for footage, for what reason, and who approved the retrieval
  4. Chain and contract layer (stage 3+) — Joint-controller arrangement: Purposes and duties allocated across JV partners, essence published; Subcontract flow-down: Capture, retention, deletion, sub-processors and model training, priced; Supplier processing terms: Instructions-only processing, and what may happen to derived data
  5. Close-out and handover layer (stage 4+) — Handover data schedule: Agreed at award, priced in the close-out, executed at practical completion; Deletion evidence: Certificates from every holder, including suppliers and sub-processors; Information-model review: Personal data in the model identified, justified or redacted before transfer
Step-by-step insights
Site capture — the decisions are physical and they are made once
Where a camera points, how much of the neighbouring street it frames, what resolution it records at and whether a mask sits over the welfare unit are decisions made by an installer on a wet Tuesday in week two, and they set the ceiling on everything above. Software minimisation cannot recover a design that captures too much: a blurred region in a viewer is a display setting, while a masked sensor region is a fact about what was recorded. Specify framing and masking in the package, and inspect it at commissioning the way you would inspect any other installed system.
Identity and transparency — hold the join, publish the notice
The induction register is the most powerful artefact on a site because it is the one that makes everything else personal data. Treat it accordingly: separate store, access-logged, and identity resolution only on a recorded request from a named role. The other half of this layer is the notice, and it fails for practical rather than legal reasons — the audience is transient, multilingual and in a hurry. A poster at the turnstile with three sentences and a contact address does more real work than a comprehensive policy nobody opens.
Project record — a register that a site can maintain
The corporate register lists what the company does; the project register lists what this site does, and it has to be maintainable by a project team with no privacy background. In practice that means one page per system, updated when a package is let or a supplier ships a change, with the retention setting recorded next to the person who verified it. Attach the DPIA to the same page. If maintaining the record needs a specialist, it will lag the site by exactly the interval between site visits.
Chain and contract — the layer that crosses company boundaries
Everything above this layer is inside one company's control and everything below it depends on other people doing what they agreed. That is why it is the layer that decides whether a project is genuinely Controlled or merely tidy: without written allocation and flow-down, a well-run camera estate sits inside a chain where nobody has said who answers a worker, what a subcontractor may do with an alert, or whether the supplier may train on the imagery. It is drafted at award and it is worth commercial attention, because a term nobody priced is a term nobody honours.
Close-out — the layer that exists only if it was scoped early
Every other layer has an obvious owner while the project runs. This one has none, because its owner is a project that no longer exists. The mechanism that works is contractual and boring: a schedule agreed at award, a close-out task with a budget line, deletion certificates as a condition of final payment, and a named surviving organisation for anything that legitimately persists. Projects that skip it do not fail an audit on the day — they fail one three years later, when a client discovers an archive with no controller and no reason to exist.

The layer most often skipped is the third, and skipping it is what makes the rest unprovable. A project can have masked cameras, a card-first turnstile and a genuinely proportionate model, and still be unable to answer a client's auditor because nothing records which of those decisions was made, by whom, or on what date. The register and the request log cost a few hours a month and they are what convert a well-run site into a demonstrably well-run site — which, in front of a regulator or a union representative, is the only version that counts.

A 90-day plan: one site's camera and turnstile estate

The Unmapped-to-Evidenced move made concrete on the system every project already runs — a CV camera estate and an access gate that nobody has registered, based or closed out.

Ninety days is enough to take one site's monitoring estate from unmapped to evidenced, provided the scope is held to one project and two systems. The estate to start with is the camera network and the access gate, because they exist on every site, they touch every person who passes through it, and every artefact they need — register entry, LIA, Article 9 analysis, DPIA, flow-down terms, handover schedule — is reusable by the next system and the next project. The plan below assumes the equipment is already installed and working: the quarter contains governance engineering and procurement, not a security package. Scoped to a portfolio instead of a site, the same work takes two years, and the discipline is saying no to breadth.

Unmapped → Evidenced on one site's monitoring estate, in one quarter

One project, one owner pair — the project data lead and the site manager, with the privacy lead on call. If a phase needs more than its window, narrow the scope to fewer devices rather than extending the plan.

  1. Days 1–15

    Walk the site and build the register

    Physically walk the site with the systems supplier and record every camera, reader, tag and capture device: what it frames, what analytics run on it, who can view it, where the recording lives, and what the retention setting actually is rather than what the policy says. Include the kit subcontractors brought — drones, 360 cameras, their own site apps. Name the owner pair and open the project register.

    A device-level register that matches what is on the ground

  2. Days 16–40

    Fix the basis, the notice and the consultation

    Run the legitimate-interests assessment on the camera estate purpose by purpose, and the Article 9 analysis on the gate — with a genuine card route offered and timed, not merely available. Complete the site DPIA before any further analytics are energised. Consult union or works-council representatives and record what changed as a result. Rewrite the gate notice so an agency operative can understand it in the two minutes they will give it.

    A signed site DPIA, an offered alternative at the gate, and a notice people can actually use

  3. Days 41–65

    Enforce minimisation and retention in the equipment

    Make the paperwork true in the kit: re-aim and mask cameras that see beyond the hoarding or into welfare areas, set alerting to emit zone and event rather than identity by default, configure retention on the recorder and verify it against the oldest file, put identity resolution behind a logged request from two named roles, and publish the drone flight plan with notice to workers and neighbours.

    Controls enforced by the equipment and verified against the register

  4. Days 66–90

    Close the chain and pre-agree the handover

    Draft the joint-controller arrangement for the shared systems and publish its essence at the gate. Issue flow-down terms in the next packages covering capture, retention, deletion and model training, priced. Fix the supplier's terms on derived data. Write the handover data schedule — destination and evidence per class — and agree it with the client's team. Then run a dry access request from an operative and time it end to end, suppliers included.

    A written allocation, priced flow-down and a handover schedule signed long before it is needed

The order matters

  1. Register before assessment

    The DPIA, the LIA and the notice all describe the estate, so the register comes first or every document is fiction. The most common way this quarter fails is a team that writes the assessments in week one and discovers in week nine that the site has eleven more cameras than the assessment describes, two of them pointing at a neighbouring building.

  2. Basis before equipment changes

    Let the balancing test tell you which angles, resolutions, analytics and retention periods have to change. Reconfiguring first means reconfiguring twice, because the assessment routinely lands somewhere the engineers did not predict — usually tighter on retention and looser on coverage than anyone expected.

  3. Handover decided at the start, not the end

    The disposal schedule is the one artefact that cannot be produced when it is needed, because by then the project is demobilising. Write it in the first quarter while the supplier still wants the next order and the client's team is still meeting you weekly. It takes an afternoon in month three and it is unbuyable in month thirty-six.

Failure modes that turn a site estate into an incident

Four quiet regressions account for most of the exposure on projects — and each one has a preventive measure that costs a fraction of its consequence.

Governance failures on a project are quiet by nature: the cameras keep recording, the gate keeps working, the alerts keep arriving, and the distance between what the paperwork says and what the site does widens without a single alarm. The four modes below account for most of the incidents that end in a client's audit finding, a union escalation or an unanswerable access request. None of them is exotic, all of them are cheap to prevent, and each becomes dramatically more expensive after handover, when the people who could have fixed it have moved to another project.

Likelihood: highImpact: high

The analytics update nobody assessed

The camera supplier ships a software release that adds people-counting, dwell-time or behaviour classification, enabled by default or offered as a free upgrade the site manager accepts. The estate is now doing something the DPIA never described, the notice never mentioned and the workforce was never told about — and the change arrived through a maintenance window rather than a decision.

PreventionA contractual duty on the supplier to notify feature changes, plus an assessment trigger wired to supplier releases — new capability, new screening, before it is switched on.

Likelihood: highImpact: medium

The safety camera becomes the claims camera

Footage collected to keep people out of an exclusion zone starts answering commercial questions: who was on the deck when the pour slipped, which gang was slow, who left the gate open. Each request is individually defensible and collectively fatal, because the basis, the assessment and the notice all describe safety, and a regulator or a union will read the retrieval log before it reads the policy.

PreventionA retrieval log recording requester, reason and approver, reviewed monthly by the project director — and a stated rule that any new purpose needs an assessment, not a favour.

Likelihood: mediumImpact: high

The joint venture dissolves and the data does not

The JV completes, the partners demobilise and the corporate vehicle winds up — leaving a camera archive, a set of biometric templates and an access database whose controller no longer exists as a legal person. The first access request or client query afterwards has no addressee, and each former partner discovers it carries the whole obligation for a system it thought somebody else ran.

PreventionThe Article 26 arrangement names a surviving owner for every class and a close-out step at dissolution, written into the JV deed at formation rather than negotiated at wind-up.

Likelihood: mediumImpact: medium

The supplier's retention default outlives your project

The recorder was set to thirty days and the cloud platform was not; the supplier's standard is a rolling twelve months, mirrored to a second region, retained until the account closes. The project deletes its own copy at completion and the archive continues quietly, still identifiable, on infrastructure the contractor no longer pays for and cannot inspect.

PreventionRetention stated as a contractual specification per storage location, verified at commissioning, with a deletion certificate covering every holder as a condition of final payment.

Glossary

Hover a term for its definition — or expand the map full screen. The full definitions are written out below.

Joint controllers
Two or more organisations that jointly determine why and how personal data is processed. On a project this is the default position for shared site systems specified by a JV or project board, and it arises from the facts of the decision rather than from anything the contract says.
Article 26 arrangement
The written allocation joint controllers must make of their respective duties — transparency, data-subject rights, security, breach notification — with the essence of it made available to the people in the data. On a site that means at the gate and in the induction, not on a corporate website.
Induction identity join
The link between a credential (card, tag, face) and a named person and employer, created when someone is inducted onto a site. It is the single hop that makes camera, turnstile and tag data personal data, and holding it separately with logged access is the strongest minimisation control a project has.
Systematic monitoring
Continuous or repeated observation of people, as opposed to observation triggered by an incident. An always-on camera estate or access system is systematic even if nobody watches the feed, which is why it counts toward the threshold for a mandatory impact assessment.
DPIA
A data protection impact assessment: the documented process of identifying and mitigating risks to individuals before high-risk processing starts. On a project it belongs in the site set-up programme, signed before a system is energised, and reopened when the site or the software changes.
Biometric template
The mathematical representation of a face or fingerprint used to recognise a specific person. Processing one to identify someone is special category data under Article 9, so it needs an additional condition beyond the ordinary lawful basis — which is why most site gates are better served by cards.
Special category data
Data revealing health, biometrics used for identification, trade-union membership and other protected characteristics, processed only under Article 9's narrower gates. Sites walk into it through biometric gates, fatigue wearables, occupational health records and any monitoring that reveals who attends union meetings.
Purpose limitation
The principle that data collected for one specified purpose may not be reused for an incompatible one. It is the principle site estates breach most often, because footage gathered for safety is the easiest source of answers to commercial, quality and disciplinary questions.
Common data environment (CDE)
The project's shared information store under ISO 19650, holding models, drawings, photographs and records that several organisations produce and consume. It is also the route by which identifiable site imagery travels into the client's permanent asset record.
Health and safety file
The information about residual risks in the completed asset that CDM 2015 requires be passed to the client at the end of a project. It is a defined, purposeful record — not a licence to hand over the project's monitoring archive alongside it.
Golden thread
The digital record of building information that must be kept and handed over for higher-risk buildings in England, which the GOV.UK guidance requires to be managed in a way that complies with data protection law. Like the safety file, it compels specific information, not an archive.
Deletion certificate
A dated statement from whoever holds data — contractor, supplier or sub-processor — listing the systems and volumes destroyed. On a project it is the practical proof of close-out, and making it a condition of final payment is the cheapest enforcement mechanism available.

Frequently asked questions

The questions project, privacy and commercial teams ask most often when GDPR meets a live site.

Do we need a DPIA for AI safety cameras on a construction site?

Almost certainly yes, and before the system is energised rather than after. Computer-vision site monitoring meets several Article 35 triggers at once: it monitors people systematically, it evaluates their behaviour, the people in the data are in a dependent position, and on a large site it operates at scale. Two triggers is the working threshold and a CV camera estate usually meets four. Scoped to one site and one system, a first assessment is typically two to three weeks of work, most of it the device-level mapping the project needs for its own register anyway.

Can we use biometric turnstiles for site access?

Only if you can evidence why a card or fob will not do. Processing biometric data to identify someone is special category data, so it needs an Article 9 condition on top of an ordinary lawful basis, and in an employment setting consent is fragile because refusal has to be genuinely consequence-free. The ICO ordered Serco Leisure and associated trusts to stop biometric attendance monitoring for more than 2,000 employees and destroy the data, precisely because less intrusive means were available and no real alternative had been offered. If you do proceed, the non-biometric route must be as quick and as visible as the biometric one.

Who is the controller for site CCTV on a joint venture?

Usually the JV partners jointly, because the decision to install the system and what it is for was taken together. Article 26 applies on the facts, so an undocumented JV does not avoid joint control — it simply leaves every partner carrying the full obligation with no allocation of who does the work. Write an arrangement that allocates transparency, rights handling, security and breach duties, publish its essence at the gate and in the induction, and name one contact point that answers workers regardless of which partner employs them.

Is our subcontractor a processor or a controller for the drone footage it captures?

It depends on who decided the purpose, not on what the subcontract calls it. If you instructed a survey subcontractor to capture progress imagery to your specification and it may not use it otherwise, it is acting as a processor and needs Article 28 terms. If it flies for its own measurement, claims or marketing purposes, it is a controller for that processing — on your site, capturing your inducted workforce and your neighbours. Either way the capture belongs in your project register, and the package should state plainly what may be captured, kept, reused or published.

What happens to site CCTV footage at practical completion?

It should be deleted, with evidence, unless a specific live matter justifies keeping a defined extract. Raw footage exists for deterrence, incident investigation and dispute evidence, and none of those purposes survives the project by years. The practical mechanism is a handover data schedule agreed at contract award: each class gets a destination — delete, anonymise or transfer — and deletion certificates from every holder, including the camera supplier's cloud platform, are made a condition of final payment. Deciding this on the last day of a project is how archives end up with no owner.

Can we hand the site data over to the client with the building?

Some of it, on a stated basis, with a named receiving controller. The health and safety file must go to the client under CDM 2015, and for higher-risk buildings the golden thread must be handed over and kept digitally — GOV.UK's guidance is explicit that the information must be managed in a way that complies with data protection law. Those duties compel specific building information, not the monitoring archive. Progress and as-built imagery can transfer where the asset record needs it, after a review that redacts identifiable people the record does not require.

Do we have to consult the union or works council before installing site monitoring?

In much of Europe, yes, and everywhere it is the cheapest evidence you can gather. Article 88 lets member states set their own rules for processing in employment, including through collective agreements, and EU law on informing and consulting employees applies on top. In Germany, works councils have co-determination rights over technical devices capable of monitoring workers, which in practice means agreement before installation. The AI Act adds a duty on employers deploying high-risk systems to inform workers' representatives and affected workers before putting them into service. Record the consultation and what changed because of it.

Can we train a model on our site footage?

Only with a basis for that specific purpose, and 'we already hold the footage' is not one. Reuse has to be compatible with the purpose the imagery was collected for, or carry a fresh basis of its own. The EDPB's opinion on AI models confirms that personal data inside a training pipeline remains personal data and that a claim of model anonymity has to be demonstrated rather than assumed. The commercial version of the question matters just as much: if your camera supplier proposes to improve its detector on your site imagery, that is the supplier's own purpose, and the contract must say whether it is permitted.

Does the EU AI Act apply to construction site monitoring?

Yes, in parallel with GDPR rather than instead of it. AI intended to monitor and evaluate the performance and behaviour of people at work falls in the AI Act's high-risk category, which captures PPE and behaviour analytics, productivity inference and allocation models. Deployer duties include competent human oversight, relevant input data, retention of system logs and informing workers' representatives before the system goes into service. Inferring emotions in the workplace is prohibited outright. GDPR continues to govern the personal data inside those systems throughout, and the efficient response is one set of evidence referenced from both files.

Do drone surveys of a site need a DPIA, and what about the neighbours?

Usually yes, and the neighbours are the harder half. Aerial capture across a large site records workers and, at the boundary, people who were never inducted and never saw a notice — gardens, windows, footpaths, adjoining offices. Aviation rules from the CAA or EASA govern the flying and say nothing about the recording, so complying with one is not complying with the other. Plan flight lines to the red line, publish the schedule and a notice, mask or discard imagery beyond the boundary, and review progress footage before any of it is published externally.

How long can we keep site access and turnstile records?

As long as a named duty or purpose requires, field by field, and no longer. Access records are usually a mixture: some fields exist for statutory employment, tax, immigration or safety duties with their own periods, some exist for evacuation roll call and expire the moment the shift ends, and some exist because the system captured them by default. The honest exercise is to map each field to the duty that compels it, keep those, and delete the rest at demobilisation. Biometric templates are the clearest case of all — after the last shift there is no purpose, so they should be destroyed.

We are the client, not the contractor. Are we exposed?

You are, wherever you specified something. A client that requires biometric enrolment, mandates a camera specification, or asks for gate reports naming individuals has decided a purpose and is a controller for it, whatever the works information calls the arrangement. Clients also inherit the risk at the other end: the information model and asset records you accept at handover may contain identifiable site imagery, and once inside your estate they sit under a retention policy written for buildings. Ask for the handover data schedule at award, and ask for deletion certificates at completion.

About the author

Atomic Loops Engineering

Industrial AI practice

Atomic Loops builds production AI systems for construction, infrastructure, manufacturing and energy operators — computer vision on site, progress and quality analytics, forecasting and decision support running against live project data. Governance is an engineering deliverable in that work: retention, masking, role-gated access and the evidence pack are built into the system rather than written about it afterwards.

  • · Computer-vision and site-analytics systems delivered on live projects with principal contractors
  • · Retention, masking and access controls implemented in the capture and storage layer, not in policy documents
  • · DPIA and handover evidence packs produced alongside the engineering, with operator DPOs and project directors
  • · 32 cited sources on this page

Sources

  1. EUR-LexRegulation (EU) 2016/679 (GDPR) — full text (opens in a new tab)
  2. gdpr-info.eu (Intersoft Consulting)Article 5 GDPR — principles relating to processing (opens in a new tab)
  3. gdpr-info.eu (Intersoft Consulting)Article 6 GDPR — lawfulness of processing (opens in a new tab)
  4. gdpr-info.eu (Intersoft Consulting)Article 9 GDPR — processing of special categories of personal data (opens in a new tab)
  5. gdpr-info.eu (Intersoft Consulting)Article 26 GDPR — joint controllers (opens in a new tab)
  6. gdpr-info.eu (Intersoft Consulting)Article 28 GDPR — processor (opens in a new tab)
  7. gdpr-info.eu (Intersoft Consulting)Article 35 GDPR — data protection impact assessment (opens in a new tab)
  8. gdpr-info.eu (Intersoft Consulting)Article 88 GDPR — processing in the context of employment (opens in a new tab)
  9. EUR-LexRegulation (EU) 2024/1689 (AI Act) — full text (opens in a new tab)
  10. European CommissionRegulatory framework for AI (opens in a new tab)
  11. EUR-LexDirective 2002/14/EC — informing and consulting employees (opens in a new tab)
  12. Federal Ministry of Justice (Germany)Works Constitution Act (Betriebsverfassungsgesetz), English translation (opens in a new tab)
  13. European Data Protection BoardGuidelines 3/2019 on processing of personal data through video devices (opens in a new tab)
  14. European Data Protection BoardGuidelines 07/2020 on the concepts of controller and processor (opens in a new tab)
  15. European Data Protection BoardOpinion 28/2024 on data protection aspects of AI models (opens in a new tab)
  16. Article 29 Data Protection Working PartyOpinion 2/2017 on data processing at work (WP249) (opens in a new tab)
  17. Information Commissioner's OfficeEmployment practices and data protection: monitoring workers (opens in a new tab)
  18. Information Commissioner's OfficeCCTV and video surveillance guidance (opens in a new tab)
  19. Information Commissioner's OfficeBiometric data guidance: biometric recognition (opens in a new tab)
  20. Information Commissioner's OfficeData protection impact assessments (DPIAs) (opens in a new tab)
  21. Information Commissioner's OfficeGuidance on AI and data protection (opens in a new tab)
  22. Information Commissioner's OfficeICO orders Serco Leisure to stop using facial recognition technology (opens in a new tab)
  23. Information Commissioner's OfficeEnforcement action: Serco Leisure Operating Limited and associated trusts (opens in a new tab)
  24. Information Commissioner's OfficeConstruction employment deny list (opens in a new tab)
  25. Health and Safety ExecutiveConstruction health and safety (opens in a new tab)
  26. Health and Safety ExecutiveConstruction (Design and Management) Regulations 2015 (opens in a new tab)
  27. GOV.UKKeeping information about a higher-risk building: the golden thread (opens in a new tab)
  28. ISOISO 19650-1 — organisation and digitisation of information about buildings (opens in a new tab)
  29. UK BIM FrameworkUK BIM Framework (opens in a new tab)
  30. UK Civil Aviation AuthorityDrones and model aircraft — the rules (opens in a new tab)
  31. European Union Aviation Safety AgencyCivil drones (unmanned aircraft) (opens in a new tab)
  32. FPS Employment, Labour and Social Dialogue (Belgium)Specific formalities for construction works: declaration of works and presence registration (opens in a new tab)

Find out where your projects stand — then fix the weakest dimension

We run the assessment with your project, privacy and commercial leads, review the site systems rather than the paperwork, and leave you with a costed 90-day plan for the weakest dimension on one live project. You keep the plan whether or not we build it.

Published · Last updated

Benchmark request

Tell us where to send it

Benchmark for this page

Used once, to send this benchmark and follow it up personally. No newsletter, no automated sequences.